Regulatory brief · NIST AI RMF

Four functions, and the evidence each one asks for.

The NIST AI Risk Management Framework 1.0 is voluntary, sector-neutral, and the vocabulary almost every other AI framework borrows — including Treasury's financial-services adaptation. It is organised around four functions: GOVERN, MAP, MEASURE, MANAGE.

Why a voluntary framework matters here

NIST AI RMF creates no legal obligation. It matters because it became the shared vocabulary: Treasury's FS AI RMF is an explicit adaptation of it, and examiners increasingly frame questions in its terms.

Its practical value is that it separates stating a control from evidencing one. Most AI governance programmes are strong on GOVERN and MAP, which are documentation exercises, and thin on MEASURE and MANAGE, which require running systems that produce artefacts.

The four functions, and what we produce for each

FunctionWhat it asksEvidence Sentinel produces
GOVERNAccountability structures, policy, culturePolicy versioning; RBAC; governance-mode changes recorded with a named accountable owner; hash-chained audit
MAPContext, inventory, use-case understandingModel inventory with materiality tiering; agent classification; compliance tagging; Know Your Agent dossiers
MEASURETesting, metrics, evaluationDisparate impact against the four-fifths rule; drift monitoring; monthly QA sampling with disagreement rate; release-gated eval sets
MANAGERisk response, prioritisation, remediationEnforced guardrails; kill switches; escalation queue; governance modes for staged rollout

Note where the weight sits. GOVERN and MAP we support with records. MEASURE and MANAGE are where an inline decision gate has something the documentation-first tools do not: the controls actually ran, and the artefact proving it is chained.

Scope, honestly

Mapping to a function is not conformance

We map capabilities to the four functions. We do not claim Sentinel makes an institution NIST AI RMF conformant — the framework covers organisational practices, workforce, and lifecycle decisions well outside what any single product touches. Treat this as the subset a decision gate can evidence.

Sources

Check every claim above. We would rather you did.

If we have characterised any of this incorrectly, tell us and we will correct the page.

Design partners

Start where the evidence is thinnest.

Most programmes can describe their governance and cannot evidence their measurement. A two-week shadow run produces the MEASURE artefacts before you commit to anything.